Vulnerability index

Browse CVEs

56 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.4 CVE-2014-2269EPSS 16% modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a reques… Vtiger Crm Patch available Fix from $1,6002014-04-22 HIGH 7.5 CVE-2013-3213 Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklis… Vtiger Crm No fix yet Fix from $1,9502014-04-02 MEDIUM 6.5 CVE-2013-5091 SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL… Vtiger Crm after 5.4.0 Fix from $1,6002013-10-04 MEDIUM 5.0 CVE-2012-4867 Directory traversal vulnerability in modules/com_vtiger_workflow/sortfieldsjson.php in vtiger CRM 5.1.0 allows remote attackers to read arbitrary fil… Vtiger Crm No fix yet Fix from $1,6002012-09-06 HIGH 7.5 CVE-2011-4559 SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the … Vtiger Crm after 5.2.1 Fix from $1,9502011-11-28 MEDIUM 6.8 CVE-2010-3910EPSS 7% Multiple directory traversal vulnerabilities in the return_application_language function in include/utils/utils.php in vtiger CRM before 5.2.1 allow … Vtiger Crm after 5.2.0 Fix from $1,6002010-11-26 MEDIUM 6.0 CVE-2010-3909 Incomplete blacklist vulnerability in config.template.php in vtiger CRM before 5.2.1 allows remote authenticated users to execute arbitrary code by u… Vtiger Crm after 5.2.0 Fix from $1,6002010-11-26 HIGH 9.0 CVE-2009-3258 vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters, (4) vie… Vtiger Crm Mitigation only Fix from $1,9502009-09-18 HIGH 9.0 CVE-2009-3250EPSS 11% The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary cod… Vtiger Crm No fix yet Fix from $1,9502009-09-18 HIGH 7.5 CVE-2009-3249EPSS 10% Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot do… Vtiger Crm No fix yet Fix from $1,9502009-09-18 MEDIUM 6.8 CVE-2009-3248 Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin u… Vtiger Crm No fix yet Fix from $1,6002009-09-18 MEDIUM 5.0 CVE-2008-3458 Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail … Vtiger Crm after 5.0.3 Fix from $1,6002008-08-04 HIGH 8.5 CVE-2007-3599 vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the View permis… Vtiger Crm after 5.0.2 Fix from $1,9502007-07-06 MEDIUM 6.5 CVE-2007-3603 SQL injection vulnerability in the dashboard (include/utils/SearchUtils.php) in vtiger CRM before 5.0.3 allows remote authenticated users to execute … Vtiger Crm after 5.0.2 Fix from $1,6002007-07-06 MEDIUM 6.5 CVE-2007-3616 index.php in vtiger CRM before 5.0.3 allows remote authenticated users to perform administrative changes to arbitrary profile settings via a certain … Vtiger Crm after 5.0.2 Fix from $1,6002007-07-06 MEDIUM 5.5 CVE-2007-3598 index.php in vtiger CRM before 5.0.3 allows remote authenticated users to obtain all users' names and e-mail addresses, and possibly change user sett… Vtiger Crm after 5.0.2 Fix from $1,6002007-07-06 MEDIUM 5.5 CVE-2007-3602 The SOAP webservice in vtiger CRM before 5.0.3 does not ensure that authenticated accounts are active, which allows remote authenticated users with i… Vtiger Crm after 5.0.2 Fix from $1,6002007-07-06 HIGH 7.5 CVE-2006-5289EPSS 8% Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in th… Vtiger Crm No fix yet Fix from $1,9502006-10-13 HIGH 7.5 CVE-2006-4617 Unrestricted file upload vulnerability in fileupload.html in vtiger CRM 4.2.4, and possibly earlier versions, allows remote attackers to upload and e… Vtiger Crm after 4.2.4 Fix from $1,9502006-09-07 HIGH 7.5 CVE-2006-4588 vtiger CRM 4.2.4, and possibly earlier, allows remote attackers to bypass authentication and access administrative modules via a direct request to in… Vtiger Crm No fix yet Fix from $1,9502006-09-06 MEDIUM 6.8 CVE-2006-4587 Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 4.2.4, and possibly earlier, allow remote attackers to inject arbitrary web script … Vtiger Crm Mitigation only Fix from $1,6002006-09-06 HIGH 7.5 CVE-2005-3819 Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authenticatio… Vtiger Crm after 4.2 Fix from $1,9502005-11-26 HIGH 7.5 CVE-2005-3822 Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username in… Vtiger Crm after 4.2 Fix from $1,9502005-11-26 HIGH 7.5 CVE-2005-3823 The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parame… Vtiger Crm after 4.2 Fix from $1,9502005-11-26 MEDIUM 6.4 CVE-2005-3820 Multiple directory traversal vulnerabilities in index.php in vTiger CRM 4.2 and earlier allow remote attackers to read or include arbitrary files, an… Vtiger Crm after 4.2 Fix from $1,6002005-11-26 MEDIUM 5.0 CVE-2005-3824 The uploads module in vTiger CRM 4.2 and earlier allows remote attackers to upload arbitrary files, such as PHP files, via the add2db action. Vtiger Crm after 4.2 Fix from $1,6002005-11-26